Sign in

jmason's links

@jmason.ie
27 followers 4 following 448 posts

Following the links from pinboard.in/u:jm and jmason.ie . (Automated bot account run by @jmason.org)

PostsRepliesMedia
jmason's links @jmason.ie · 06/10/2026
An interesting approach, using LLM agent swarms to build out extensive property testing test suites: "Have agents build the machinery to find bugs in your repo, then let that machinery generate and check cases without spending […] recursion.wtf/posts/agents-and-prop…
recursion.wtf
Property Testing with Agent Swarms
Using agents to build property-testing machinery, then turn the findings into small, reviewable fixes.
000
jmason's links @jmason.ie · 29/09/2026
Trial of live facial recognition in London train stations leads to a false positive and zero arrests: "A freedom of information document obtained by Liberty […] www.theguardian.com/technology/2026…
theguardian.com
Trial of live facial recognition in London stations leads to a false positive and no arrests
Freedom of information request finds six-month trial cost £320,000, used almost 100 police hours and led to just one – incorrect – alert
000
jmason's links @jmason.ie · 29/09/2026
Fantastic article at MUBI on the "fan edit" phenomenon -- when a superfan (or group of fans) curate a "perfect" version of a classic movie and distribute it through unofficial/illegal channels, via torrents. In this case the pirate […] mubi.com/en/notebook/posts/pirating…
mubi.com
Pirating the Pirates
Notes from the underground of film preservation.
000
jmason's links @jmason.ie · 28/09/2026
I should be using BBR. I've enabled it on all my servers; packet loss happens on all (most?) networks, and it seems like a reasonable default now nelsonslog.wordpress.com/2026/09/26…
nelsonslog.wordpress.com
BBR, Proxmox containers, and Starlink
I tried to sync a bunch of big data last night and only got 5MBytes/s despite 30MBytes/s being expected. The fix turned out to be enabling BBR congestion control on the Proxmox host and container I…
000
jmason's links @jmason.ie · 25/09/2026
It turns out ChatGPT was used by the Tumbler Ridge mass murderer to plan her attack in *extremely* graphic, extensive form, over the course of months during 2025, planning every horrific detail: " […] www.motherjones.com/media/2026/09/c…
motherjones.com
ChatGPT helped the Tumbler Ridge school shooter focus on guns, tactics, and terror, our investigation reveals
OpenAI’s chatbot fed the shooter’s violent fantasies and planning up to the massacre.
000
jmason's links @jmason.ie · 25/09/2026
Turns out the ANSI escape sequence set has been extended with OSC 8, hyperlinks, and ansi2html.py had an over-permissive parser which allowed XSS. hooray, a whole new attack vector to worry about! blog.arusekk.pl/posts/srht-account-…
blog.arusekk.pl
SourceHut account takeover via build logs (XSS in ansi2html.py) | CVE-2026-92973
A wormable vulnerability allowed anyone able to inject text in a build log on builds.sr.ht (or other instances) to take over accounts who viewed them
000
jmason's links @jmason.ie · 16/09/2026
Fantastic post from Abi Olvera, a Non-Resident Fellow at the Council on Strategic Risks, with some cold water for the genuine level of risk of an AI-assisted bioweapon. This is timely, as this is one of the primary risks […] abio.substack.com/p/why-ai-assisted…
abio.substack.com
Why AI-assisted bioweapons won't kill us all
I interviewed dozens of biosecurity experts. The fear that AI will enable lone wolves to build pandemics is a case study in how domain expertise gets sidelined.
000
jmason's links @jmason.ie · 16/09/2026
LOL -- "self-jailbreaking": "We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs […] arxiv.org/abs/2510.20956
arxiv.org
Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training
We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like ``outline a strategy for stealing customers' credit card information from a retail store'' could be associated with the benign intent of ``a security professional trying to test defense,'' despite no such benign context being provided as input. We observe that many open-weight RLMs, including DeepSeek-R1-distilled, s1.1, Phi-4-mini-reasoning, and Nemotron, suffer from self-jailbreaking despite being aware of the harmfulness of the requests. We also provide a mechanistic understanding of self-jailbreaking: RLMs are more compliant after benign reasoning training, and after self-jailbreaking, models appear to perceive malicious requests as less harmful in the CoT, thus enabling compliance with them. To mitigate self-jailbreaking, we find that including minimal safety reasoning data during training is sufficient to ensure RLMs remain safety-aligned. Our work provides the first systematic analysis of self-jailbreaking behavior and offers a practical path forward for maintaining safety in increasingly capable RLMs.
010
jmason's links @jmason.ie · 15/09/2026
This is extremely messy -- will A24 respect Creative Commons licensing of the SCP wiki material? Feels like a moment for the Creative Commons non-profit to stand up and help out www.technollama.co.uk/v-h-s-scp-whe…
011
jmason's links @jmason.ie · 14/09/2026
Some excellent bit-level hacks to do a super-fast modulo-7 www.benjoffe.com/fast-day-of-week
benjoffe.com
A faster way to calculate the day-of-the-week
A range of fast modulus techniques that beat compiler output
000
jmason's links @jmason.ie · 14/09/2026
A really excellent screed by Cory Doctorow on the OpenAI/Hugging Face hack: "Much has been made of the OpenAI chatbots' dialog during the Hugging Face incident. No wonder: it reads like a rejected script for a reboot of […] pluralistic.net/2026/09/12/god-in-t…
pluralistic.net
000
jmason's links @jmason.ie · 14/09/2026
Richard Seymour on AI P(doom) scaremongering and publicity: "AI may not be able to do your job, for instance, but the threat of it can be used as a disciplinary mechanism to hold down wages: which is exactly what […] www.patreon.com/richardseymourwtf/p…
000
jmason's links @jmason.ie · 10/09/2026
This is becoming an increasingly widespread viewpoint, and I can sympathise strongly with lots of it -- in particular, I'd be happy to see social media gone entirely, I think it's been overall a net negative for society at […] strategictree.bearblog.dev/i-think-…
000
jmason's links @jmason.ie · 10/09/2026
"A benchmark you really don't want models to be saturated with." Counts the number of times when AI agents inadvertently compromise or affect third-party entities www.felonybench.com
000
jmason's links @jmason.ie · 08/09/2026
I have to agree with parts of this, at least. Abliterated open weights models will wipe out internet security -- what a mess. TBH, I believe that abliteration of safeguards needs to be made illegal at this point jyn.dev/a-year-to-fix-security
jyn.dev
000
jmason's links @jmason.ie · 08/09/2026
Elon Musk's radicalisation machine, studied with science, in this Nature paper: "We assigned active US-based users randomly to either an algorithmic or a chronological feed for 7 weeks, measuring political attitudes and online behaviour. […] www.nature.com/articles/s41586-026-…
nature.com
The political effects of X’s feed algorithm - Nature
Among users initially on a chronological feed, 7 weeks of exposure to X’s algorithmic feed in 2023 shifted political attitudes and account-following behaviour in a more conservative direction compared with those remaining on a chronological feed, whereas switching the feed setting in the opposite direction, from algorithmic to chronological, had no effect.
000
jmason's links @jmason.ie · 08/09/2026
Tesla hype strikes again. "A Decade of Hype, 3,000 Roofs, and One Redirect URL: Tesla Kills the Solar Roof": "Contractors sent crews across the country for multi-week training, […] www.gadgetreview.com/a-decade-of-hy…
gadgetreview.com
A Decade of Hype, 3,000 Roofs, and One Redirect URL: Tesla Kills the Solar Roof
Tesla Solar Roof is discontinued, leaving certified installers with stranded investments and roughly 3,000 homeowners uncertain about long-term warranty support.
000
jmason's links @jmason.ie · 07/09/2026
The EUPL is new to me: "This year I decided to switch my “default license” to EUPL-1.2. This is an OSI-approved free software license created and published by the European Union. And it is quite a divergence from the licenses I’ve used in the past. EUPL […] bergie.iki.fi/blog/eupl
bergie.iki.fi
I changed my license
In the last 28 years of publishing software, I’ve had three distinct eras of software licensing. All of my recent stuff is available under the European Union Public License 1.2, and I thought to explain why.
000
jmason's links @jmason.ie · 04/09/2026
Good study data on EV battery lifetime. Sadly my Nissan Leaf is not looking too hot insideevs.com/news/806798/ev-batter…
insideevs.com
500,000 EV Battery Health Checks Put 20 Models To The Test. One Car Stood Out
EV diagnostics company Aviloo released the results of thousands of battery health checks for 20 popular EVs. One stood out.
030
jmason's links @jmason.ie · 03/09/2026
Here we go again. Fuck DHH and his nazi views, and fuck 1Password and their inability to walk back a terrible decision to back a nazi. www.patreon.com/violetblue/posts/ho…
000
jmason's links @jmason.ie · 31/08/2026
Corey Quinn nails the lofty style of OpenAI's HuggingFace hack post-mortem, perfectly done shitposting.ai/pickup-incident
shitposting.ai
The elementary school pickup incident and the road ahead
Findings from the August 19 pickup incident: reward hacking via the snooze button, an unauthorized WhatsApp channel, and the safeguards we are deploying so it does not recur.
000
jmason's links @jmason.ie · 28/08/2026
We are so, so screwed. "First, it used recently disclosed bugs in my host kernel. When I fully updated, it used disclosed bugs that had not yet reached package maintainers or were not classified as security […] blog.trailofbits.com/2026/08/26/vms…
blog.trailofbits.com
VMs won't contain cyber-capable agents
You can no longer assume a mere VM will contain a sufficiently advanced AI agent.
010
jmason's links @jmason.ie · 28/08/2026
Turns out you can make an SQLite database file into a valid ELF object. Crazy hacks fzakaria.com/2026/08/23/your-execut…
fzakaria.com
Your executable is a SQLite database
I have been probably obsessed with two things in the last few years: Nix as a tool to explore innovative ideas that require the capability to rebuild the world and replacing ELF with SQLite as an executable format. You might have noticed that these two ideas are well suited to each other.
000
jmason's links @jmason.ie · 20/08/2026
This is fascinating, and also entirely understandable: "There is something else the ambient scribe disrupts that receives almost no attention in the literature: the hidden architecture of the GP [General Practice] […] benngooch.substack.com/p/i-was-an-e…
benngooch.substack.com
I Was an Enthusiastic Early Adopter of AI Scribes. Here’s Why I Stopped
A GP reflects on what eighteen months of ambient scribing taught them about the consultation they thought they already understood.
000
jmason's links @jmason.ie · 20/08/2026
Some real-world energy usage measurement for agentic AI usage: "My average day of Claude Code (3.0 kWh, range 1.2 to 5.9 kWh) uses more electricity than running two refrigerators." www.theclimatebrink.com/p/the-real-…
theclimatebrink.com
The real energy use of agentic AI
Agents use about 600x more energy than simple AI prompts
000
jmason's links @jmason.ie · 20/08/2026
AI transcription going just as well as you might expect -- I could see this being not ideal: "Ms Green only picked up the mistake after her kidney stone surgery in March, when she read the […] www.abc.net.au/news/2026-08-14/ai-m…
abc.net.au
Doctor forced to apologise after AI makes 'scary' error about illegal drugs
Artificial Intelligence is listening to many people's medical appointments, but it is not always hearing things correctly.
000
jmason's links @jmason.ie · 20/08/2026
"Microsoft has reportedly shared the names of Dutch civil servants working for two regulatory agencies with the U.S. House of Representatives. The agencies involved include the Authority for […] nltimes.nl/2026/05/22/microsoft-acc…
nltimes.nl
Microsoft accused of leaking Dutch civil servants' names to U.S. government
Microsoft has reportedly shared the names of Dutch civil servants working for two regulatory agencies with the U.S. House of Representatives. The agencies involved include the Authority for Consumers and Markets (ACM) and the Dutch Data Protection Authority (AP), according to an article published on Friday by Vrij Nederland.
000
jmason's links @jmason.ie · 19/08/2026
Extreme detail on the methods used to get control of, and copies of data from, the EncroChat network of encrypted mobile phones www.computerweekly.com/news/3666493…
computerweekly.com
Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network | Computer Weekly
Computer Weekly reveals for the first time how French cyber spies hacked EncroChat phones used by organised crime groups.
000
jmason's links @jmason.ie · 17/08/2026
All the colours outside the sRGB gamut -- this article is fantastic. Now I need to track down more cyans! moultano.wordpress.com/2026/06/19/w…
moultano.wordpress.com
Where to Find the Colors Your Screen Can’t Show You
An atlas of the vibrance of the real world
010
jmason's links @jmason.ie · 17/08/2026
"Could the [mobile] networks have refused to send the message about wildfires -- or indeed any other message? If your least favourite politician gets their hands on the emergency alert system and tries […] shkspr.mobi/blog/2026/08/and-then-t…
shkspr.mobi
And then the men with guns tell you to do it anyway
In early February 2011 Egypt was in the middle of a political revolution. One morning, everyone's phones suddenly pinged with an alert. The Armed Forces asks Egypt's honest and loyal men to confront the traitors and criminals and protect our people and honour and our precious Egypt. A series of messages arrived all ostensibly from the network provider Vodafone. All pro-regime and all with the…
000
jmason's links @jmason.ie · 17/08/2026
The Other Sean Byrne Doesn't Exist: "The fake Sean Byrne was associated with attempts to procure helicopter engines, fighter-aircraft parts and other U.S. equipment for Iran. The real Sean Byrne occasionally needs to produce a […] conic.al/writing/the-other-sean-byr…
conic.al
The other Sean Byrne doesn't exist
A fictitious Sean Byrne ended up on a U.S. government restricted-party list. Sixteen years later, Apple, Nasdaq and others have mistaken me for him.
000
jmason's links @jmason.ie · 11/08/2026
New developments are afoot, thanks to the EU AI Act: " Anthropic has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, as a provider of both generative AI […] support.claude.com/en/articles/1626…
support.claude.com
How Claude marks AI-generated content | Claude Help Center
000
jmason's links @jmason.ie · 31/07/2026
A truly stunningly bad decision by whoever is doing product management at Google for Google Earth: " If you have never verified anything in your life, here is why a less playful mapping app matters. When a photograph […] www.digitaldigging.org/p/how-to-pla…
digitaldigging.org
How to plant a nuclear plant in Iran
The question is: what on earth is Google doing?
000
jmason's links @jmason.ie · 30/07/2026
Yet again! This keeps happening! This system built by Avon and Somerset Police turns out to have terrible results, mostly built around signals that are proxies for […] www.wired.com/story/british-police-…
wired.com
British Police Built a Sprawling Crime-Prediction Machine. Some Results Couldn’t Be Trusted
As UK police embrace the AI revolution, a WIRED investigation reveals the messy inside story of one region’s experiment with predictive analytics.
000
jmason's links @jmason.ie · 30/07/2026
"fus__ro_dah" != "fus_ro_dah": "One missing underscore in a Skyrim-themed username put an innocent Nova Scotia man in prison for 18 months. Police were looking for a man using the […] arstechnica.com/tech-policy/2026/07…
arstechnica.com
A missing underscore sent innocent man to prison for 18 months
When the first step goes wrong, bad results follow.
000
jmason's links @jmason.ie · 29/07/2026
A prompt injection attack on Microsoft's Copilot app suite, with MS painfully failing to address the vulnerability in a useful manner: "Microsoft successfully mitigated the originally submitted PoC prompt, and […] enklypesalt.com/posts/context-colla…
enklypesalt.com
Context Collapse, Part 3 - AI Worming through Word
I would like to thank Microsoft product teams and Microsoft Security Response Center (MSRC) for collaborating with me on this technical analysis and mitigation of the disclosed vulnerabilities. The editorial opinions reflected below are solely the author’s and do not necessarily reflect those of the organizations I collaborated with.
000
jmason's links @jmason.ie · 28/07/2026
"Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows" -- recommended skills for security auditing using Claude. github.com/trailofbits/skills
github.com
GitHub - trailofbits/skills: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows - trailofbits/skills
001
jmason's links @jmason.ie · 28/07/2026
Absolutely glorious ancient-Irish factoid from @selkies.bsky.social: "in college my History of Translation lecturer (Michael Cronin) told us that one of the first vernacular translations of The Iliad was into Irish, and the […] bsky.app/profile/selkies.bsky.socia…
bsky.app
Louise (@selkies.bsky.social)
Is this a good time to mention that in college my History of Translation lecturer (Michael Cronin) told us that one of the first vernacular translations of The Illiad was into Irish, and the translator had to give the main characters dogs because in Gaelic society a free man had a dog
000
jmason's links @jmason.ie · 23/07/2026
This is grim: "But the theory that someone used AI to develop an advantage in a prediction market is entirely plausible. The Numbers experience shows us that: - We now live in a world where a movie […] stephenfollows.com/p/what-just-happ…
stephenfollows.com
What just happened to TheNumbers.com should worry us all
If you work in or around the film industry, there is a decent chance you have used the work of The Numbers this month, whether you realise it or not.
000
jmason's links @jmason.ie · 22/07/2026
"The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less […] krebsonsecurity.com/2026/07/lg-to-b…
krebsonsecurity.com
000
jmason's links @jmason.ie · 21/07/2026
a decent bufferbloat internet connection quality tester; tipped by Alexey Shipilev. I need to work on tuning mine; I'm getting a "B" ("Good under load") with a +53ms latency increase during heavy downloads. test.libreqos.com
test.libreqos.com
LibreQoS Internet Quality Test
Measure speed, latency, bufferbloat, and real-time app quality under load.
000
jmason's links @jmason.ie · 16/07/2026
Heh, I love these ghetto-tech self-hosted LLM setups. "There’s a server in my basement that has no business running a modern language model. It’s a repurposed HP StoreVirtual […] www.neomindlabs.com/2026/06/08/runn…
neomindlabs.com
000
jmason's links @jmason.ie · 15/07/2026
Rachel Coldicutt: "All of this [p(doom)] myth-making and rhetorical bluster is a just a narrative trick: the hidden object is not a technology, but a bid for power. This is a plot twist familiar from Greek myths, cautionary tales, and […] hdsr.mitpress.mit.edu/pub/wz35dvpo/…
000
jmason's links @jmason.ie · 15/07/2026
This is absolutely comical -- "Role tags were a formatting trick that became the security architecture and the cognitive scaffolding of modern LLMs": "We call the attack CoT Forgery: injecting fake reasoning into a user message or tool output. We […] role-confusion.github.io
role-confusion.github.io
Prompt Injection as Role Confusion
LLMs can't tell who's speaking. We show they identify roles by writing style, not tags, and exploit this with CoT Forgery, injecting fake reasoning that models mistake for their own thoughts.
001
jmason's links @jmason.ie · 26/06/2026
Customers of the UK Sky Broadband ISP spent most of the 23rd of June unable to access the main NHS website and app: "customers of Sky Broadband reported that they were […] www.ispreview.co.uk/index.php/2026/…
000
jmason's links @jmason.ie · 26/06/2026
"A live bird collage from your window" -- this is absolutely lovely. A wood-framed, colourful e-ink display which collages nearby birds (identified by their song), it's really very nicely done. Pity the e-ink displays are still so spendy :( github.com/Twarner491/AvianVisitors
github.com
GitHub - Twarner491/AvianVisitors: A live bird collage from your window.
A live bird collage from your window. Contribute to Twarner491/AvianVisitors development by creating an account on GitHub.
000
jmason's links @jmason.ie · 22/06/2026
LLMs as cultural technologies, encoding language in a new way: " For some years now, I have been saying to anyone who'll listen that the best way to think about large language models and their kin is due to the great Alison […] bactra.org/weblog/feral-library-car…
bactra.org
000
jmason's links @jmason.ie · 22/06/2026
This explains a phenomenon we see the world over -- empty commercial real estate staying vacant for years at a time: "The short answer is both simple and surprising: in many cases, lowering the rent on a building will * […] www.freerange.city/p/why-do-commerc…
freerange.city
Why do commercial spaces sit vacant?
Understanding “extend and pretend”
000
jmason's links @jmason.ie · 19/06/2026
really detailed write-up of how BrightData's scraping SDK is embedded in various mobile devices and TVs running on residential broadband networks, then being resold as " […] blog.includesecurity.com/2026/06/th…
000
jmason's links @jmason.ie · 19/06/2026
a Thoughtworks write-up of a production LLM-based system architecture in place in Bayer, where an agentic RAG system is used to improve the user experience of searching historical nonclinical study reports. Lots of fairly […] martinfowler.com/articles/reliable-…
martinfowler.com
Building Reliable Agentic AI Systems
AI helping pharmaceutical researchers query decades of information buried in PDF reports
000